Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mh69-97fr-wj66

Опубликовано: 17 июн. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Sitecore Experience Manager (XM), Experience Platform (XP), and Experience Commerce (XC) versions 9.0 through 9.3 and 10.0 through 10.4 are affected by a Zip Slip vulnerability. A remote, authenticated attacker can exploit this issue by sending a crafted HTTP request to upload a ZIP archive containing path traversal sequences, allowing arbitrary file writes and leading to code execution.

Sitecore Experience Manager (XM), Experience Platform (XP), and Experience Commerce (XC) versions 9.0 through 9.3 and 10.0 through 10.4 are affected by a Zip Slip vulnerability. A remote, authenticated attacker can exploit this issue by sending a crafted HTTP request to upload a ZIP archive containing path traversal sequences, allowing arbitrary file writes and leading to code execution.

EPSS

Процентиль: 99%
0.80802
Высокий

8.8 High

CVSS3

Дефекты

CWE-23

Связанные уязвимости

CVSS3: 8.8
nvd
8 месяцев назад

Sitecore Experience Manager (XM), Experience Platform (XP), and Experience Commerce (XC) versions 9.0 through 9.3 and 10.0 through 10.4 are affected by a Zip Slip vulnerability. A remote, authenticated attacker can exploit this issue by sending a crafted HTTP request to upload a ZIP archive containing path traversal sequences, allowing arbitrary file writes and leading to code execution.

CVSS3: 8.8
fstec
12 месяцев назад

Уязвимость систем управления контентом Sitecore Experience Manager (XM), Experience Platform (XP) и платформы для персонализированного процесса покупок Experience Commerce (XC), связанная с ошибками в обработке относительного пути к каталогу, позволяющая нарушителю получить доступ к записи произвольных файлов и выполнить произвольный код

EPSS

Процентиль: 99%
0.80802
Высокий

8.8 High

CVSS3

Дефекты

CWE-23